Skip to main content

Privacy Policy

Last updated: 2026-06-28

This Privacy Policy explains how Vocograph collects, uses, shares, retains, and protects your personal information when you use the Platform. It applies to all visitors, fans, and creators. Please read it carefully alongside our Terms of Service.

1. Identity and Contact Details of the Data Controller

Vocograph is the data controller responsible for your personal information under applicable data protection law. Vocograph is currently operated as a sole proprietorship doing business under the trade name "Vocograph," established in France. These details will be updated to reflect the legal entity name and registered address upon completion of formal business entity formation.

For all privacy-related inquiries, data subject access requests, complaints, or questions about this Privacy Policy, you may contact us at: [email protected]. We endeavor to respond to all privacy inquiries within 30 days.

At the current scale of our operations, Vocograph is not required to appoint a Data Protection Officer under Article 37 of the GDPR. Vocograph does not carry out large-scale systematic monitoring of individuals, nor does it process special categories of data on a large scale as its core activity. If this changes as the Platform grows, we will appoint a DPO and update this Policy accordingly. In the meantime, all privacy matters may be directed to the contact email above.

For users located in the European Union, the relevant lead supervisory authority is determined by Vocograph's country of establishment. For users located in the United Kingdom, the relevant supervisory authority is the Information Commissioner's Office (ICO).

Vocograph has not yet designated a UK representative under UK-GDPR Article 27. UK users may contact us directly at [email protected].

2. Data We Collect and How

We collect personal information in several ways: directly from you when you create an account or use the Platform, automatically through your use of the Platform, and from third-party services that support our operations.

Account data: When you create an account, we collect your name, email address, and profile photo. Creator accounts additionally provide biographical information and an artist or stage name.

Creator identity and payment data: During creator onboarding, additional identity information — including date of birth — is collected directly by our payment processor Stripe as part of its identity verification and Know Your Customer (KYC) process. Vocograph receives only a verification status confirmation from Stripe. We do not collect, receive, or store the raw date of birth, government-issued identity documents, or other sensitive KYC materials submitted to Stripe. Creator payout account details (bank account or debit card information) are collected and stored exclusively by Stripe.

Fan-submitted content: When a fan submits a voice autograph request, we collect the personal message included with the request and any photo the fan uploads. These are stored on the Platform for the purpose of order fulfillment.

Creator-submitted content: When a creator delivers a voice autograph, we store the voice recording on our infrastructure for delivery to the purchasing fan and for ongoing access through the collectible.

Transaction data: We collect and retain records of all orders placed through the Platform, including order history, the product price and fees paid, fulfillment status, delivery timestamps, and associated payment transaction identifiers.

Usage and technical data: We automatically collect certain technical information when you access the Platform, including your IP address, browser type and version, device type and operating system, referring URL, pages visited, session duration, and similar usage data. This information is collected through server logs and is used for security, fraud prevention, and legal compliance purposes.

Communications: We retain records of transactional emails sent to you through our email provider Resend, including order confirmations, delivery notifications, and account-related notices.

Vocograph does not directly collect or store payment card numbers, card verification codes, or other sensitive payment credentials. All payment card data is handled entirely by Stripe in accordance with applicable Payment Card Industry Data Security Standards (PCI-DSS).

3. Legal Basis for Processing

This section applies to users located in the European Union (under the General Data Protection Regulation, "GDPR") and in the United Kingdom (under the UK General Data Protection Regulation and the Data Protection Act 2018, collectively "UK-GDPR"). We process your personal data on the following lawful bases:

Contract performance (GDPR Article 6(1)(b)): We process account data, transaction data, fan-submitted content, creator-submitted content, and payment-related data as necessary to perform our contract with you — specifically, to create and maintain your account, process orders, deliver voice autograph collectibles, and disburse creator earnings.

Legitimate interests (GDPR Article 6(1)(f)): We process usage and technical data (IP addresses, browser information, session data) for fraud prevention, platform security, abuse detection, and enforcement of our Terms of Service. We have assessed that these legitimate interests are not overridden by your rights and freedoms because: the data involved is limited to technical identifiers rather than sensitive personal content; the processing is necessary and proportionate to the specific security and fraud-prevention purposes pursued; and the impact on you is minimal given that this data is not used for profiling, marketing, or any purpose beyond platform security and legal compliance.

Legal obligation (GDPR Article 6(1)(c)): We retain transaction and payment records as required by applicable tax, accounting, and financial reporting laws. We may also process personal data to comply with court orders, regulatory requests, or other compulsory legal process.

Consent (GDPR Article 6(1)(a)): Where we send marketing or promotional communications (as distinguished from transactional emails necessary to operate the Platform), we will do so only with your prior consent. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. Non-essential cookies, if any, are set only after you provide opt-in consent through our cookie consent mechanism.

For users located in the United Kingdom: your rights are governed by the UK-GDPR and the Data Protection Act 2018, which are substantively equivalent to the EU GDPR but constitute a separate legal instrument. The relevant supervisory authority for UK users is the Information Commissioner's Office (ICO). References to "GDPR" in this Policy should be read as including the UK-GDPR where applicable to UK users.

4. How We Use Your Data

We use the personal information we collect for the following specific purposes:

Operating the Platform: Creating and maintaining your account, authenticating your identity, displaying your profile to other users as appropriate to your role (fan or creator), and providing the core marketplace functionality.

Fulfilling orders: Processing voice autograph requests, transmitting fan-submitted messages and photos to the designated creator, storing and delivering completed voice recordings, and managing the fulfillment lifecycle including auto-cancellation of unfulfilled orders.

Processing payments: Facilitating authorization holds, payment capture upon delivery, creator payout disbursements through Stripe Connect, and managing chargebacks and payment disputes.

Communicating with you: Sending transactional emails related to your account and orders, including order confirmations, delivery notifications, account security notices, and legal or policy updates.

Moderation and enforcement: Reviewing user-generated content (including messages, photos, and recordings) to enforce our Terms of Service, investigate reported violations, resolve disputes between users, and respond to legal requests.

Fraud prevention and security: Analyzing usage patterns, IP addresses, and account activity to detect and prevent fraudulent conduct, unauthorized access, and abuse of the Platform.

Tax and legal compliance: Maintaining records required by applicable tax, accounting, and regulatory obligations.

Improving the Platform: Analyzing aggregate, de-identified usage data to improve Platform performance, reliability, and user experience.

Vocograph does not sell your personal data to any third party. Vocograph does not use your personal data for advertising targeting on behalf of third parties. Vocograph does not use your personal data for profiling or automated decision-making that produces legal or similarly significant effects, except as described in Section 17 of this Policy. We do not use your data for any purpose not listed in this Section without first obtaining your consent or establishing another lawful basis for processing.

5. Data Sharing and Third-Party Processors

We share your personal data with the following third-party service providers, each of which acts as a data processor processing data on Vocograph's behalf and subject to contractual data protection obligations:

Stripe, Inc. (payment processing): Stripe processes all payments on the Platform, including fan payment authorizations, payment capture, and creator payout disbursements through Stripe Connect. For these activities, Stripe acts as a data processor on Vocograph's behalf. However, for certain activities — including creator identity verification (KYC), Stripe's own fraud detection and risk scoring, and compliance with financial regulations — Stripe acts as an independent data controller under its own Privacy Policy and terms of service. Vocograph has no control over and is not responsible for Stripe's independent processing activities. Stripe receives transaction amounts, payment method details, and — for creators — identity verification documents submitted directly to Stripe during onboarding. Stripe's processing of your data is governed by Stripe's Privacy Policy and, for creators, the Stripe Connected Account Agreement.

Supabase, Inc. (database hosting): Supabase hosts the Platform's primary database infrastructure, which stores account data, order records, and application data. Supabase processes this data on Vocograph's instructions pursuant to a data processing agreement.

Cloudflare, Inc. (object storage): Cloudflare R2 stores audio recordings (creator voice autographs) and image files (fan-uploaded photos, collectible card assets). Cloudflare processes this data on Vocograph's instructions pursuant to a data processing agreement.

Resend (email delivery): Resend transmits transactional emails on Vocograph's behalf, including order confirmations, delivery notifications, and account-related notices. Resend receives recipient email addresses and email content as necessary to deliver these communications.

Vocograph does not share your personal data with any third party for that party's own independent marketing, advertising, or commercial purposes. We may disclose your personal data to third parties outside the processors listed above only in the following circumstances: to comply with a valid legal obligation, court order, subpoena, or regulatory request; to protect the rights, property, or safety of Vocograph, our users, or the public; to enforce our Terms of Service; or in connection with a merger, acquisition, or sale of all or substantially all of Vocograph's assets, in which case we will provide notice as described in our Terms of Service.

6. Voice Recordings: Special Notice

Voice recordings created and delivered through the Platform have heightened sensitivity under the privacy laws of several jurisdictions. This section provides specific disclosures about how voice recordings are collected, stored, used, and retained.

What recordings are created: Only creators produce voice recordings on the Platform. Fans do not create or upload audio content. Each recording is a personalized voice autograph created by a creator in response to a specific fan request.

Purpose of collection: Voice recordings are collected and stored solely for the purpose of fulfilling voice autograph orders and delivering the completed collectible to the purchasing fan. Recordings are not used for any other purpose.

Storage and security: Voice recordings are stored on Cloudflare R2 with encryption at rest. Access to stored recordings is limited to the purchasing fan (through the Platform's delivery interface) and to Vocograph personnel for the purposes of content moderation, dispute resolution, and enforcement of our Terms of Service.

No AI training or biometric identification: Vocograph does not use voice recordings to train artificial intelligence models, machine learning systems, or any automated system. Vocograph does not use voice recordings for biometric identification, voiceprint analysis, speaker recognition, or any purpose related to identifying or authenticating individuals by their voice characteristics.

Retention and deletion: Voice recordings associated with delivered orders are retained for the duration described in Section 8 of this Policy. Upon a valid deletion request from the creator or other data subject, Vocograph will delete the stored copy of the recording from its infrastructure as described in Section 11 of this Policy.

Biometric data classification notice: The laws of certain U.S. states classify voice recordings or voiceprints as biometric data and impose specific consent, retention, and disclosure requirements. Illinois: The Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14/1 et seq., classifies biometric identifiers — including voiceprints — as protected data and requires informed written consent before collection, a publicly available retention and destruction schedule, and prohibits the sale or profiting from biometric data. Statutory damages under BIPA range from $1,000 to $5,000 per violation, with a private right of action. Texas: The Texas Capture or Use of Biometric Identifier Act (CUBI Act), Tex. Bus. and Com. Code Ann. § 503.001, restricts the capture and use of biometric identifiers — including records of voice — for commercial purposes without informed consent. Washington State: Washington's biometric identifier laws (RCW 19.375) regulate the collection and use of biometric identifiers in commercial contexts. If you are a resident of Illinois, Texas, or Washington State: by using the Platform as a creator and delivering voice recordings, you acknowledge this disclosure and consent to the collection, storage, and use of your voice recordings as described in this Privacy Policy, solely for the purposes of order fulfillment, delivery, content moderation, and dispute resolution. Vocograph does not extract, store, or process voiceprints or biometric templates from voice recordings. Voice recordings are retained and deleted in accordance with the schedule in Section 8 of this Policy.

7. Fan-Uploaded Photos: Special Notice

When a fan uploads a photo as part of a voice autograph request, that photo is stored on the Platform's infrastructure and used solely for the purpose of embedding it into the collectible card delivered to the fan. This section provides specific disclosures about how fan photos are handled.

Purpose: Fan-uploaded photos are used exclusively for order fulfillment — specifically, to embed the photo into the digital collectible card that accompanies the delivered voice autograph. Fan photos are not used for any other purpose.

Third-party depictions: As stated in our Terms of Service, fans warrant that any uploaded photo does not depict identifiable third parties without those persons' documented consent. Vocograph does not independently verify the identity of individuals depicted in fan-uploaded photos and relies on the fan's representation and warranty.

No facial recognition or biometric use: Vocograph does not use fan-uploaded photos for facial recognition, biometric identification, image analysis, machine learning training, or any automated processing beyond the technical steps necessary to embed the photo into the collectible card.

Retention and deletion: Fan-uploaded photos associated with delivered orders are retained for the duration described in Section 8 of this Policy. Upon account deletion, fan photos will be deleted from Vocograph's systems within 30 days, subject to the limited exceptions described in Section 8 for data required for legal compliance or dispute resolution. A photo that has already been embedded into a delivered collectible card cannot be retroactively removed from that card without also affecting the fan recipient's collectible — see Section 11 for details on this conflict.

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, or as required by applicable law. The following retention schedule applies by data category:

Active account data (name, email, profile photo, biographical information, preferences): Retained for the lifetime of your active account. Deleted or anonymized within 30 days of account deletion, subject to the exceptions below.

Order data, including voice recordings and fan-uploaded photos: Retained for 3 years following delivery of the completed order, for the purposes of dispute resolution, chargeback defense, and legal compliance. After the retention period, order data is deleted or anonymized unless retention is required by a specific legal obligation.

Payment and transaction records (order amounts, payment identifiers, commission calculations, payout records): Retained for 7 years following the transaction, as required by applicable tax and accounting laws.

IP address logs and usage data: Retained for 90 days from the date of collection, for security, fraud detection, and abuse prevention purposes. After the retention period, IP logs are deleted or anonymized.

Transactional email records: Retained for 1 year following transmission.

Upon account deletion, Vocograph will delete or anonymize your personal data within 30 days, with the following exceptions: (a) data that Vocograph is required to retain under applicable tax, accounting, or financial reporting law (such as payment records retained for 7 years); (b) data that forms part of a delivered collectible where the recipient fan holds a valid license to that collectible under our Terms of Service, and where deletion would conflict with the fan's license rights — see Section 11 for details; (c) data subject to an active legal hold, pending dispute, or ongoing investigation; and (d) aggregated or de-identified data that can no longer reasonably be linked to you.

Vocograph does not retain personal data indefinitely. If you believe we are retaining your data beyond the periods described above, please contact us at [email protected].

9. International Data Transfers

Vocograph is established in the United States, and our primary infrastructure providers — Supabase, Cloudflare, and Stripe — may store and process data in the United States and other jurisdictions outside your country of residence.

For users located in the European Union: Transfers of personal data from the EU to the United States or other countries that have not received an adequacy decision from the European Commission are made pursuant to the Standard Contractual Clauses (SCCs) adopted under the post-Schrems II framework (Commission Implementing Decision (EU) 2021/914), or where applicable, pursuant to an adequacy decision. We have verified that each of our primary processors (Supabase, Cloudflare, and Stripe) offers Standard Contractual Clauses as a transfer mechanism for EU personal data. Where a processor maintains EU-region data residency options on our service plan, we will use commercially reasonable efforts to configure EU data residency where technically feasible.

For users located in the United Kingdom: Transfers of personal data from the UK to countries outside the UK that have not received an adequacy regulation from the UK Secretary of State are governed by the UK's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as applicable. We have verified that each of our primary processors offers an appropriate UK transfer mechanism.

For users located in other jurisdictions with restrictions on cross-border data transfers: We comply with applicable transfer requirements in your jurisdiction to the extent required by law. If you have questions about the specific transfer mechanisms applicable to your data, please contact us at [email protected].

10. Your Rights

Depending on your jurisdiction, you may have specific rights regarding your personal data. This section summarizes the rights available under the major privacy regimes applicable to our users.

European Union (GDPR) and United Kingdom (UK-GDPR): You have the right to access your personal data and obtain a copy; the right to rectification of inaccurate or incomplete data; the right to erasure ("right to be forgotten"), subject to the limitations described in Section 11; the right to restriction of processing in certain circumstances; the right to data portability (receiving your data in a structured, commonly used, machine-readable format — Vocograph will provide this as JSON or CSV); and the right to object to processing based on legitimate interests. You also have the right to lodge a complaint with your local supervisory authority. For UK users, the relevant authority is the Information Commissioner's Office (ICO).

California (CCPA/CPRA): Vocograph extends CCPA/CPRA rights to all California residents as a matter of practice, regardless of whether Vocograph meets the statutory thresholds that trigger mandatory CCPA obligations. California residents have the right to know what personal information we collect, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information (Vocograph does not sell or share personal information as defined by the CCPA/CPRA — we state this here for transparency), and the right to limit the use of sensitive personal information. California residents also have the right to non-discrimination for exercising their privacy rights. We will not deny you services, charge different prices, or provide a different quality of service because you exercise your CCPA/CPRA rights. To exercise your opt-out right, contact us at [email protected] with the subject line 'CCPA Opt-Out Request' As Vocograph does not sell or share personal information, no data will be sold or shared pending or following your request.

California — Shine the Light (Civil Code § 1798.83): Vocograph does not share personal information with third parties for those parties' own direct marketing purposes. California residents may submit a written request for details about any such sharing to [email protected], though no such disclosure will be required given our current practices.

California — Do Not Track: The Platform does not currently alter its data collection or processing practices in response to browser 'Do Not Track' signals. If Vocograph implements Do Not Track signal recognition in the future, this section will be updated.

California — Global Privacy Control (GPC): The Platform does not currently recognize Global Privacy Control signals. As Vocograph does not sell or share personal information, no sale or sharing will occur regardless of GPC signal status. This will be reassessed if Vocograph introduces advertising or data-sharing practices in the future.

Other U.S. States: Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other U.S. states with comprehensive consumer data privacy laws in effect have rights similar to those described above, including rights of access, deletion, correction, portability, and opt-out of targeted advertising, profiling, and data sales. To exercise these rights, contact us at [email protected]. We will respond to verified requests within 45 days, with a possible 45-day extension upon notice.

Canada (PIPEDA and Quebec Law 25): Canadian residents have the right to access their personal information held by Vocograph, the right to challenge the accuracy and completeness of their information and have it amended, and the right to withdraw consent to the collection, use, or disclosure of their personal information, subject to legal or contractual restrictions and upon reasonable notice.

Brazil (LGPD): Brazilian residents have rights substantively similar to those provided under the GDPR, including the right to confirmation of processing, access, correction, anonymization, portability, deletion, and information about sharing with third parties. The relevant supervisory authority for Brazilian users is the Autoridade Nacional de Proteção de Dados (ANPD).

To exercise any of these rights, contact us at [email protected] with a description of your request and sufficient information to verify your identity. For identity verification, we will ask you to provide the email address associated with your account and one additional piece of identifying information (such as your display name or a recent order reference). We will respond to verified requests within 30 days under GDPR, UK-GDPR, PIPEDA, and LGPD, or within 45 days under the CCPA/CPRA (with a possible 45-day extension upon notice to you if reasonably necessary). We will not charge a fee for the first request in any 12-month period, except where requests are manifestly unfounded or excessive.

Vocograph does not require you to create an account to submit a privacy request. If you are not a registered user, we will use the information you provide in your request to search our systems for data associated with you.

11. Right to Erasure — Delivery Conflict Disclosure

The right to erasure ("right to be forgotten") creates a specific conflict in the context of a marketplace that delivers personalized digital content. This section discloses how Vocograph handles that conflict for both creators and fans.

Creator erasure requests: If a creator requests erasure of their personal data, including voice recordings they have delivered through the Platform, Vocograph will delete the stored copies of those recordings from its infrastructure (Cloudflare R2) and delete or anonymize the creator's account data. However, Vocograph cannot ensure deletion of recordings that have already been delivered to and potentially downloaded by fans. Once a recording has been delivered, the fan may have saved a copy to their personal device. Vocograph has no technical ability to reach into a fan's device and delete downloaded content. The erasure applies to Vocograph's stored copy only.

Fan erasure requests: If a fan requests erasure of their personal data, Vocograph will delete the fan's account data, including their name, email, profile photo, and personal messages submitted with requests. However, Vocograph cannot retroactively remove a fan's photo from a collectible card that has already been assembled and delivered. The fan's photo is embedded in the collectible at the time of delivery. Deleting the source photo from Vocograph's storage does not alter collectible cards already in the fan's possession. If the fan uploaded a photo depicting themselves, and that photo was embedded in a collectible delivered to them, the erasure removes Vocograph's stored copy but does not affect the fan's own downloaded copy of the collectible.

Both directions of this conflict are inherent to any platform that delivers personalized digital content. Vocograph processes all valid erasure requests to the fullest extent within its technical control — meaning deletion from Vocograph's own servers and infrastructure — but cannot guarantee deletion from end-user devices, third-party caches, or any copies that have left Vocograph's systems.

12. Children's Privacy

Vocograph permits fans who are at least 13 years of age to create accounts and use the Platform. Creators must be at least 18 years of age. Vocograph is not directed to children under the age of 13.

In the United States, the Children's Online Privacy Protection Act (COPPA) imposes specific requirements on the collection of personal information from children under the age of 13. Vocograph does not knowingly collect personal information from children under 13. We do not independently verify age at registration, but if we learn or have reason to believe that a fan user is under 13, we will promptly suspend the account, delete all associated personal data, cancel any pending orders, and release any outstanding payment authorization holds.

Users aged 13 to 17 ("Minor Users") may use the Platform as fans only. Creator accounts are restricted to users who are at least 18 years of age. Minor Users are subject to the same Terms of Service as adult fans. If you are a Minor User, you represent that your parent or legal guardian has reviewed and consented to your use of the Platform and to the collection and use of your personal information as described in this Privacy Policy.

For users located in the European Union: GDPR Article 8 requires that where processing relies on consent, children under the age of 16 must have parental or guardian consent (EU member states may lower this to 13). Minor Users aged 13–15 in the EU are permitted to use the Platform as fans on the basis of contract performance (GDPR Article 6(1)(b)) rather than consent, meaning no separate parental consent is required for the core service. However, for any processing based on consent — such as non-essential cookies or marketing communications — we will not process the data of EU users under 16 without verified parental consent.

If you are a parent or guardian and believe that your child under 13 has created a Vocograph account or that we have collected personal information from your child under 13, please contact us immediately at [email protected]. We will investigate promptly and, if confirmed, delete the child's account and all associated personal data within 30 days of confirmation.

13. Cookies and Tracking Technologies

Vocograph uses cookies and similar technologies to operate the Platform. This section describes the categories of cookies we use and how they are managed.

Strictly necessary cookies: These cookies are essential for the Platform to function and cannot be switched off. They include session authentication cookies that keep you logged in, such as `sb-[project-ref]-auth-token` (First-party, Session/duration depends on settings, Purpose: Authentication), and CSRF (Cross-Site Request Forgery) protection tokens that secure form submissions. These cookies do not collect personal information for marketing purposes and are set automatically when you use the Platform.

Functional cookies: These cookies remember your preferences and settings to provide a more personalized experience. We use the `vocograph_cookie_consent` cookie (First-party, 1 year, Purpose: Preferences) to remember your cookie consent choices. They do not track your browsing activity across other websites.

Analytics cookies: Vocograph uses Google Analytics 4 (GA4) to understand how users interact with the Platform. These cookies include `_ga` and `_ga_[container_id]` (Third-party, up to 2 years, Purpose: Analytics). These cookies are classified as non-essential and will not be set until you provide opt-in consent through our cookie consent mechanism.

Marketing cookies: Vocograph does not currently use marketing or advertising cookies. If this changes, marketing cookies will require opt-in consent before being set.

For users located in the European Union: In compliance with the ePrivacy Directive (Directive 2002/58/EC), non-essential cookies are not set on your device until you have provided affirmative opt-in consent. Strictly necessary cookies are exempt from this consent requirement. You can manage your cookie preferences at any time through the cookie consent mechanism provided on the Platform.

Server-side tracking: Independently of browser-based cookies, Vocograph logs IP addresses and basic request metadata in server-side logs maintained by Supabase for security, fraud prevention, and legal compliance purposes. This server-side logging is not controlled by browser cookie settings and is processed under the legitimate interests legal basis described in Section 3 of this Policy.

14. Email Communications

Vocograph uses Resend as its email delivery provider to send transactional communications related to your account and orders.

Transactional emails: We send emails that are necessary to operate the Platform and fulfill our contractual obligations to you. These include: order confirmation emails sent when you submit a voice autograph request, delivery notification emails sent when a completed voice autograph is ready, account security notices (such as password reset confirmations), and legal or policy update notices. Transactional emails cannot be opted out of while your account remains active, as they are integral to the operation of the service.

Non-transactional emails: If Vocograph sends marketing, promotional, or newsletter communications in the future, we will do so only with your prior opt-in consent. You may opt out of non-transactional emails at any time by using the unsubscribe link included in every such email. Opting out of marketing emails does not affect your receipt of transactional emails.

CAN-SPAM Act compliance (United States): Commercial messages sent by Vocograph comply with the requirements of the CAN-SPAM Act (15 U.S.C. § 7701 et seq.), including accurate sender identification and a clear and conspicuous opt-out mechanism. Transactional emails — such as order confirmations, delivery notifications, and account notices — are not commercial messages under CAN-SPAM and are exempt from its physical address and opt-out requirements. Opt-out requests for commercial messages are processed within 10 business days.

CASL compliance (Canada): For emails sent to recipients located in Canada, Vocograph complies with Canada's Anti-Spam Legislation (CASL, S.C. 2010, c. 23). Commercial electronic messages are sent only with express consent, which is distinct from the implied consent applicable to purely transactional communications. Recipients may withdraw consent at any time using the unsubscribe mechanism provided in each message.

15. Security Measures

Vocograph implements technical and organizational measures designed to protect your personal data against unauthorized access, alteration, disclosure, or destruction. While no system is perfectly secure and we cannot guarantee absolute security, we take the following measures:

Encryption in transit: All data transmitted between your browser and the Platform is encrypted using TLS (Transport Layer Security). API communications between the Platform and our third-party processors are also encrypted in transit.

Encryption at rest: Voice recordings and image files stored on Cloudflare R2 are encrypted at rest using Cloudflare's server-side encryption. Database records stored on Supabase are encrypted at rest using Supabase's encryption infrastructure.

Access controls: Supabase Row Level Security (RLS) policies enforce database-level access controls, ensuring that users can only access data they are authorized to view. Administrative access to production systems and personal data is restricted to authorized personnel and is limited to the minimum access necessary for operational, moderation, and legal compliance purposes.

Payment security: Vocograph does not store payment card data. All payment processing is handled by Stripe, which is PCI-DSS Level 1 certified.

Data breach notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, Vocograph will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, Vocograph will also notify affected individuals without undue delay, as required by GDPR Article 34. For users subject to U.S. state breach notification laws, we will notify affected individuals within the timeframe required by the law of their state of residence. U.S. state notification timelines vary — for example, 30 days in Florida and Colorado, and 'in the most expedient time possible' in New York — and Vocograph will apply the applicable timeline based on the affected user's state.

Vocograph does not represent or warrant that its security measures are impenetrable or that your personal data will never be accessed, disclosed, altered, or destroyed as a result of a breach. You are responsible for maintaining the security of your own account credentials.

16. Changes to This Policy

Vocograph reserves the right to update or modify this Privacy Policy at any time. When we make material changes to this Policy — including changes to the categories of data collected, the purposes of processing, the third parties with whom data is shared, or the rights available to you — we will provide notice by posting the updated Policy on the Platform and, where practicable, by sending an email notification to registered users via Resend. The effective date of the updated Policy will be reflected in the version date displayed at the top of this document.

The version of this Privacy Policy in effect at the time you accepted it is recorded alongside your Terms of Service acceptance in our systems, enabling us to demonstrate which version of this Policy governed your data processing at any point in time.

Your continued use of the Platform after the effective date of an updated Privacy Policy constitutes your acknowledgment of the updated Policy. If a change materially affects your rights under applicable data protection law, we will seek your renewed consent where required by that law.

If you do not agree with an updated Privacy Policy, you may delete your account at any time. Account deletion will be processed in accordance with the retention and deletion schedule described in Section 8 of this Policy.

17. Automated Decision-Making and Profiling

GDPR Article 22 provides that data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning them or similarly significantly affect them.

At the current stage of the Platform's operations, Vocograph does not use automated systems to make decisions about users that produce legal or similarly significant effects without human involvement. The following automated processes are in use on the Platform:

Automated order expiration: If a creator does not fulfill a voice autograph request within the 7-day fulfillment window, the order is automatically cancelled and the fan's payment authorization hold is automatically released. This is a contractual mechanism agreed to in the Terms of Service, not a profiling decision. It applies uniformly to all unfulfilled orders without regard to any personal characteristics of the creator or fan.

Stripe fraud and risk scoring: Stripe independently operates fraud detection and risk scoring systems on transactions processed through the Platform. These systems are operated by Stripe under Stripe's own privacy policy and terms of service, not by Vocograph. Vocograph does not make account decisions based on Stripe's internal risk scores, though Stripe may independently decline a transaction or flag an account under its own policies.

Vocograph does not operate recommendation algorithms, creator ranking systems, search result personalization, or any other system that uses profiling to influence the content, pricing, or availability of services presented to individual users. If any such system is introduced in the future, this section will be updated before deployment to disclose the logic involved, the significance, and the envisaged consequences of such processing, and to describe the safeguards in place, including the right to obtain human intervention.

Business registration and publisher details are available in the Legal Notice, accessible from the site footer.